Close Menu
Altcoin ObserverAltcoin Observer
  • Regulation
  • Bitcoin
  • Altcoins
  • Market
  • Analysis
  • DeFi
  • Security
  • Ethereum
Categories
  • Altcoins (3,088)
  • Analysis (3,216)
  • Bitcoin (3,830)
  • Blockchain (2,157)
  • DeFi (2,623)
  • Ethereum (2,571)
  • Event (118)
  • Exclusive Deep Dive (1)
  • Landscape Ads (2)
  • Market (2,714)
  • Press Releases (12)
  • Reddit (2,517)
  • Regulation (2,461)
  • Security (3,639)
  • Thought Leadership (3)
  • Videos (44)
Hand picked
  • This is how North Korean secret agents infiltrated major crypto protocols, researcher claims
  • Sui and Other Best Altcoins to Hold for the Next Bull Run
  • Saylor Strategy Resumes Bitcoin Accumulation Frenzy With 4,871 BTC Purchase
  • Ethereum Price Rises to $20,000: The Accumulation Zone Indicates Buying Time
  • Stuck funds on Loopring L2 – Ledger Nano S “Only V4 supported” error – Cannot withdraw, send or export account
We are social
  • Facebook
  • Twitter
  • Instagram
  • YouTube
Facebook X (Twitter) Instagram
  • About us
  • Disclaimer
  • Terms of service
  • Privacy policy
  • Contact us
Facebook X (Twitter) Instagram YouTube LinkedIn
Altcoin ObserverAltcoin Observer
  • Regulation
  • Bitcoin
  • Altcoins
  • Market
  • Analysis
  • DeFi
  • Security
  • Ethereum
Events
Altcoin ObserverAltcoin Observer
Home»Bitcoin»This is how North Korean secret agents infiltrated major crypto protocols, researcher claims
Bitcoin

This is how North Korean secret agents infiltrated major crypto protocols, researcher claims

April 6, 2026No Comments
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Advertising disclosure

Agents linked to North Korea have spent years quietly embedding themselves within crypto companies and DeFi projects.

A long-running crypto-infiltration saga

News and reports coming out of the Democratic People’s Republic of Korea tend to have a distinct conspiracy theory and action movie feel. However, they also tend to be true and not exaggerated at all.

This time, security researcher and MetaMask developer Taylor Monahan said in a post on social network

Yeahpppppp

Many DPRK computer scientists have been building the protocols you know and love since the Summer Challenge.

The “7 years of experience in blockchain development” on their CV is not a lie.

–Tay 💖 (@tayvano_) April 5, 2026

She claims that North Korean computer scientists have quietly worked on more than 40 DeFi projects over about seven years, including protocols that became known after the DeFi summer.

oh my god uhhhh like sushi, thorchain, yam, pickle, harvest, recover, swing, paid, naos, shezmu, qrolli, saffron, sifu, napier, harmony, blueberry, stabble, onering, elemental, divvy, la token, impermax, kira, cook, fantom, ankr, gamerse, metaplay, spice, beanstalk, deltaprime,…

–Tay 💖 (@tayvano_) April 5, 2026

These workers often have “real” on-chain experience (seven years of blockchain development) but operate under stolen or synthetic identities, connecting to teams through normal recruiting funnels.

His posts respond to Tim, a pseudonymous builder and public face of Titan, a DEX aggregation and routing project based in Solana, claiming that for a previous job they interviewed an extremely qualified candidate who turned out to be an agent of Lazarus, the North Korea-affiliated group that funneled billions of dollars of stolen money through cryptocurrency networks.

In a previous job, we interviewed someone who turned out to be an agent of Lazarus. he made video calls and was extremely skilled

we invited him for in-person interviews and he ultimately refused to fly, so we were successful

only later did we find his name in a Lazarus info dump…

—Tim | Titan (@timahhl) April 5, 2026

Famous crypto detective ZachXBT also responded to Tim’s post, explaining that it was not just “Lazarus”, but a network of DPRK units (Lazarus, APT38, AppleJeus, etc.) coordinated by the General Reconnaissance Bureau and optimized for financial cybercrime. Their methods rely on “basic and hard” outreach via LinkedIn, job boards, interviews, Zoom, as well as remote development roles that teams still grant far too easily.

Lazarus Group is the collective name for all state-sponsored cyber actors in the DPRK.

The main problem is that everyone lumps them together when the complexity of the threats is different.

Threats via job postings, LinkedIn, emails, Zoom or interviews are basic and under no circumstances… pic.twitter.com/NL8Jck5edN

-ZachXBT (@zachxbt) April 5, 2026

Recent sanctions from the US Treasury Department’s Office of Foreign Assets Control (OFAC) and findings from Chainalysis indicate that the DPRK’s computer networks generated $800 million in 2024 alone and moved billions in stolen crypto since 2017, fueling weapons of mass destruction (WMD) and missile programs.

New information about the Crypto-Hack On Drift protocol

The April 1 attack on the $285 million Drift Protocol reignited fears about insider threats from North Korea, particularly after the protocol itself confirmed Saturday that speculation linking the attack to North Korean hacking groups was true.

– Drift (@DriftProtocol) April 5, 2026

They attributed the attack “with medium confidence” to UNC4736, a North Korea-aligned and state-sponsored hacking group.

The protocol claimed that the attackers relied on a well-crafted social engineering strategy: fake professional personas, in-person conference interactions, and booby-trapped developer tools to compromise contributors before ultimately executing the exploit. The attackers posed as a legitimate business company, met in person with Drift contributors in multiple countries, and used entirely constructed identities with professional backgrounds and professional networks before triggering the exploit.

The attackers used common development tools by inserting malicious tasks into VS Code and Cursor configurations, providing a compromised repository that contributors were running locally without realizing it. All of these elements combined make the incident look much more like an internal-style supply chain compromise than a simple smart contract.

The day after the attack, Ledger CTO Charles Guillement linked the attack method to the $1.4 billion Bybit hack attributed to the regime’s cyber units. Then, on Friday, blockchain analytics firm Elliptic released a survey claiming that on-chain behavior, laundering methods, and network-level indicators match techniques seen in previous DPRK-related operations. Bitcoinist covered the story.

Market implications

This crypto hacking saga has transformed into a structural national security risk. Regulators and sanctions agencies are already getting stricter around the DPRK’s computer networks, and more aggressive enforcement will likely follow.

Large state-linked exploits create latent protocol risk: higher insurance premiums, potential delistings, governance infighting over restitution, and longer risk aversion periods for DeFi tokens and perp volumes.

Bitcoin, BTC, BTCUSDT

At the moment of writing, BTC trades for the highs $69k on the daily chart. Source: BTCUSDT on Tradingview.

Cover image of Perplexity. BTCUSDT chart from Tradingview.

Editorial process as Bitcoinist focuses on providing thoroughly researched, accurate and unbiased content. We follow strict sourcing standards and every page undergoes careful review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance and value of our content to our readers.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleSui and Other Best Altcoins to Hold for the Next Bull Run

Related Posts

Bitcoin

Circle Announces Quantum-Resilient Roadmap to Secure Future Digital Asset Infrastructure – News Bytes Bitcoin News

April 6, 2026
Bitcoin

DUAL is available for exchange!

April 6, 2026
Bitcoin

Solana Price Remains Under Pressure as 1.4 Million Tokens Flow Into Exchanges

April 6, 2026
Add A Comment
Leave A Reply Cancel Reply

Single Page Post
Share
  • Facebook
  • Twitter
  • Instagram
  • YouTube
Featured Content
Event

Global Games Show Riyadh: The Ultimate Creator & Influencer Hub

March 31, 2026

The fast-evolving gaming ecosystem of Riyadh is powered by solid national investment, a flourishing esports…

Event

AI Future: The leading international forum on Artificial Intelligence & Web3

March 30, 2026

On April 14–15, AI Future will gather developers, researchers, entrepreneurs, investors, and representatives of major…

1 2 3 … 81 Next
  • Facebook
  • Twitter
  • Instagram
  • YouTube

Sui and Other Best Altcoins to Hold for the Next Bull Run

April 6, 2026

Zcash (ZEC) jumps 3%, but chart suggests 20% crash risk

April 6, 2026

New income hierarchy? How Hyperliquid Overtakes Traditional Channels

April 6, 2026
Facebook X (Twitter) Instagram LinkedIn
  • About us
  • Disclaimer
  • Terms of service
  • Privacy policy
  • Contact us
© 2026 Altcoin Observer. all rights reserved by Tech Team.

Type above and press Enter to search. Press Esc to cancel.

bitcoin
Bitcoin (BTC) $ 69,467.00
ethereum
Ethereum (ETH) $ 2,148.18
tether
Tether (USDT) $ 0.999902
xrp
XRP (XRP) $ 1.35
bnb
BNB (BNB) $ 604.58
usd-coin
USDC (USDC) $ 0.999764
solana
Solana (SOL) $ 82.31
tron
TRON (TRX) $ 0.318279
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.03
staked-ether
Lido Staked Ether (STETH) $ 2,265.05